{ "info": { "_postman_id": "c3ba5232-de60-4db7-b7df-beef531cb7b1", "name": "Trellix EDR Action History Response Actions API", "description": "Endpoint Detection and Response API for advanced threat hunting, investigation, and automated response capabilities. The EDR API supports querying threat data, searching devices, retrieving action history, and executing real-time search and response actions across managed endpoints. Authentication uses OAuth 2.0 client credentials with the soc.act.tg scope.\n\nContact Support:\n Name: Trellix Support", "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json", "createdAt": "2026-07-28T03:18:46.000Z", "updatedAt": "2026-07-28T03:18:46.000Z", "lastUpdatedBy": "35240", "uid": "35240-c3ba5232-de60-4db7-b7df-beef531cb7b1" }, "item": [ { "name": "epo", "item": [ { "name": "v2", "item": [ { "name": "response-actions", "item": [ { "name": "Create a response action", "id": "78bb4c39-6269-49f9-a839-0100ca79c728", "protocolProfileBehavior": { "disableBodyPruning": true }, "request": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" } ], "body": { "mode": "raw", "raw": "{\n \"actionType\": \"run_scan\",\n \"targetDevices\": [\n \"\",\n \"\"\n ],\n \"parameters\": {}\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/epo/v2/response-actions", "host": [ "{{baseUrl}}" ], "path": [ "epo", "v2", "response-actions" ] }, "description": "Trigger an automated response action on one or more managed endpoints. Response actions include policy enforcement, scan initiation, agent wake-up, and remediation tasks." }, "response": [ { "id": "36857f0a-9675-4977-85f1-3a1c04aae1ca", "name": "Response action accepted for processing", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "key": "Accept", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"actionType\": \"run_scan\",\n \"targetDevices\": [\n \"\",\n \"\"\n ],\n \"parameters\": {}\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/epo/v2/response-actions", "host": [ "{{baseUrl}}" ], "path": [ "epo", "v2", "response-actions" ] } }, "status": "Accepted", "code": 202, "_postman_previewlanguage": "json", "header": [ { "key": "Content-Type", "value": "application/json" } ], "cookie": [], "responseTime": null, "body": "{\n \"data\": {\n \"id\": \"\",\n \"actionType\": \"\",\n \"status\": \"failed\",\n \"targetDevices\": [\n \"\",\n \"\"\n ],\n \"createdAt\": \"\"\n }\n}", "createdAt": "2026-07-28T03:18:47.000Z", "updatedAt": "2026-07-28T03:18:47.000Z", "uid": "35240-36857f0a-9675-4977-85f1-3a1c04aae1ca" }, { "id": "4a7b1268-0eac-4fe4-b9cf-218f9857457d", "name": "Invalid response action request", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"actionType\": \"run_scan\",\n \"targetDevices\": [\n \"\",\n \"\"\n ],\n \"parameters\": {}\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/epo/v2/response-actions", "host": [ "{{baseUrl}}" ], "path": [ "epo", "v2", "response-actions" ] } }, "status": "Bad Request", "code": 400, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:18:47.000Z", "updatedAt": "2026-07-28T03:18:47.000Z", "uid": "35240-4a7b1268-0eac-4fe4-b9cf-218f9857457d" }, { "id": "c40b622b-c2b7-4d26-9e84-f511fefcdd76", "name": "Unauthorized - invalid or expired access token", "originalRequest": { "method": "POST", "header": [ { "key": "Content-Type", "value": "application/json" }, { "description": "Added as a part of security scheme: bearer", "key": "Authorization", "value": "Bearer " } ], "body": { "mode": "raw", "raw": "{\n \"actionType\": \"run_scan\",\n \"targetDevices\": [\n \"\",\n \"\"\n ],\n \"parameters\": {}\n}", "options": { "raw": { "headerFamily": "json", "language": "json" } } }, "url": { "raw": "{{baseUrl}}/epo/v2/response-actions", "host": [ "{{baseUrl}}" ], "path": [ "epo", "v2", "response-actions" ] } }, "status": "Unauthorized", "code": 401, "_postman_previewlanguage": "text", "header": [], "cookie": [], "responseTime": null, "body": null, "createdAt": "2026-07-28T03:18:47.000Z", "updatedAt": "2026-07-28T03:18:47.000Z", "uid": "35240-c40b622b-c2b7-4d26-9e84-f511fefcdd76" } ], "createdAt": "2026-07-28T03:18:47.000Z", "updatedAt": "2026-07-28T03:18:47.000Z", "uid": "35240-78bb4c39-6269-49f9-a839-0100ca79c728" } ], "id": "5f6419af-c769-49ff-96ee-eb4155d5e48b", "createdAt": "2026-07-28T03:18:46.000Z", "updatedAt": "2026-07-28T03:18:46.000Z", "uid": "35240-5f6419af-c769-49ff-96ee-eb4155d5e48b" } ], "id": "430165a0-a18b-489e-bb02-5ef2f98d7769", "createdAt": "2026-07-28T03:18:46.000Z", "updatedAt": "2026-07-28T03:18:46.000Z", "uid": "35240-430165a0-a18b-489e-bb02-5ef2f98d7769" } ], "id": "7402825f-7a76-4a44-90c7-af6101b5ce82", "createdAt": "2026-07-28T03:18:46.000Z", "updatedAt": "2026-07-28T03:18:46.000Z", "uid": "35240-7402825f-7a76-4a44-90c7-af6101b5ce82" } ], "auth": { "type": "bearer", "bearer": [ { "key": "token", "value": "{{bearerToken}}", "type": "string" } ] }, "variable": [ { "key": "baseUrl", "value": "https://api.manage.trellix.com" } ] }